Privacy Policy
Your Steam account stays yours. Here is how GTF uses information.
Last updated 2026-10-09.
Who is responsible
Kiril Boshikyov operates Games That Fit (GTF) from United Kingdom. Contact info@gamesthatfit.com. UK contact address: 10D Chambers lane, London NW10 2RH, UK. (Note: Please send all urgent inquiries via email for a faster response.)
Kiril Boshikyov is the data controller for GTF’s service processing. UK data protection law applies to our UK operation; other laws can apply where their territorial requirements are met.
Steam sign-in and information we use
Steam verifies your identity; GTF never receives your Steam password. A signed cookie authenticates your Steam ID. Requested account features can retrieve your visible name, avatar, optional public profile country, library, playtime, game presence, friends’ public summaries, selected friends’ visible ownership and your achievements. Steam privacy settings apply. Without signing in you can browse public game recommendations; personal library and friend features are unavailable.
Purposes and lawful bases
We use your identity and requested account features to provide the free service under our Terms (performance of a contract). We use limited request-security data to prevent abuse and protect availability (legitimate interests). Optional device remembering follows your separate storage choice; enabling it is not a condition of public browsing. Recommendations are informational and do not make decisions with legal or similarly significant effects.
Selected friends’ public summaries and shared ownership are used for requested group recommendations and invitations on the basis of our legitimate interest in helping friends plan games, balanced against their privacy. Access is restricted to authenticated Steam-friend/plan-participant relationships. Steam visibility is not consent. Friend summaries and ownership are transient; plans retain only the information needed for the invitation. This notice is available to invitees on GTF before they sign in. A friend may contact us to object or request information.
Cookies and browser preferences
The gtf_login cookie protects a requested sign-in for up to ten minutes. The default gtf_session is a browser-session cookie whose signed token lasts no more than 24 hours. Choosing Keep Steam signed in for 7 days enables persistence for up to seven days. Both use HttpOnly, Secure and SameSite=Lax. Browser session restoration can retain session cookies.
Taste, likes, hidden games, reviews, layouts and companion choices use this tab’s storage by default. Remember my settings enables cross-visit storage on this device. Cookie settings lets you withdraw either remembering choice. Disabling remembered preferences moves them into tab storage and removes the persistent settings. The choice record lasts 180 days. GTF does not use advertising pixels or analytics cookies. The Cookie policy lists individual storage items.
Third-party requests and game facts
Steam and its media CDNs receive ordinary browser requests, including IP addresses, when providing avatars, artwork, achievements and trailers. Steam sign-in and Store checkout have Valve’s own policies. A public profile country can inform price estimates; it does not reveal the Steam account’s billing country. Where absent, a disclosed connection-country estimate or fallback is used.
A bounded Cloudflare download test measures approximate speed and stores its result in this tab for up to 30 minutes. Cloudflare receives connection metadata; we do not send it a Steam ID, account cookie or password. Server enrichment sends public game identifiers/titles to Steam, Twitch/IGDB and PCGamingWiki. It does not send them your private GTF reviews, plans or achievements. SteamDB and HowLongToBeat provide reference/source information where available; GTF does not scrape SteamDB.
Windows companion
The companion reads local Steam installation manifests and visible executable paths to identify installed/running games. Game paths and the process list stay on your PC. Optional play history counts observed running intervals, which can include pauses and menus. The app stores timer preferences, reminder snapshots and optional history in its local application-data folder.
The origin-checked, token-protected loopback connection passes your Steam ID, friend IDs/names, eligible game titles and plan snapshots for requested planning. It receives no Steam password, website cookie, API key or achievements. Planning context and queued commands stay in memory for up to 15 minutes. Local history/settings stay until cleared. Uninstalling need not remove the application-data folder. Gentle reminders do not take focus; strict check-ins are optional.
Retention and deletion
Library, friend and achievement responses are kept in browser memory. Library ownership can be cached in server memory for up to two minutes. GTF presence is visible only to authenticated Steam friends and expires after 45 seconds without an update. Plans keep participant IDs/names, games, start time, duration and replies until one day after the start. Expired plans and presence are excluded from reads; database cleanup runs every 15 minutes. An outage can delay physical deletion.
Rate-limit counters store rotating keyed digests of IP/account identifiers, not raw IPs or Steam IDs. Identifiers rotate hourly, counters expire ten minutes after use and scheduled cleanup removes expired rows. Hosting providers separately process request/security logs under their published policies. Support emails are kept for the enquiry and normally deleted within 12 months of resolution, unless an unresolved dispute or legal obligation requires longer retention.
Remembered browser preferences and local companion history stay until cleared. Signing out removes this browser’s cookie; it does not delete plans, Steam records or local history. A copied signed token remains usable until expiry or signing-key rotation. Personal plan-history dismissal hides a record for you, rather than deleting another participant’s data.
Shared public metadata
Public game facts are cached by AppID separately from ownership, friends, achievements and personal reviews. Available Steam facts normally refresh after seven days; unavailable records after a day. IGDB/PCGamingWiki evidence normally refreshes after 30 days; missing IGDB matches after seven days and missing PCGamingWiki evidence after a day. Public source links and short evidence excerpts can be retained. Server API credentials are never included in browser or companion builds.
Hosting and international access
GTF uses Vercel for website/API hosting, with its configured API region in London, and Supabase for the database in Ireland. Vercel’s CDN and providers’ support/security/subprocessor operations can involve other countries, including the United States. GitHub hosts companion downloads; Namecheap provides domain services. None of these statements promises that every request stays in the UK or Europe.
The UK permits relevant transfers to the EEA under its adequacy arrangements. Provider contracts and applicable transfer safeguards govern other processing locations; ask info@gamesthatfit.com for information about the safeguards relevant to your data. Providers can also process account, billing or security information for their own purposes under their privacy notices. Choosing a database region alone does not determine all processing locations.
Your choices, rights and complaints
You can change Cookie settings, export/clear browser preferences below, change Steam privacy, and disable/clear companion history. To request access, correction, deletion, restriction, objection or portability where applicable, email info@gamesthatfit.com. We verify identity proportionately and answer rights requests within one month, explaining any lawful extension. Withdrawing consent does not affect earlier lawful processing. We cannot delete your Steam account or Valve’s records.
Please send privacy complaints to the same email. We acknowledge complaints within 30 days, investigate, keep you informed and respond without undue delay. You may complain to the UK Information Commissioner’s Office (ICO), including if you are dissatisfied with our response.
Security, adults and updates
GTF uses HTTPS, server-only credentials, signed cookies, origin checks, access restrictions and shared request limits. These reduce risk without guaranteeing absolute security. GTF is intended for adults; if we learn that a child has supplied personal information contrary to this intended use, we investigate, restrict relevant processing and remove information where appropriate. Do not submit sensitive personal information in game plans.
We assess suspected incidents, contain exposure and notify regulators/affected people where the applicable breach-reporting requirements are met. Material privacy changes receive a dated notice; new optional data uses require an appropriate choice. The date above identifies this version.
Your browser data
These controls act only on GTF preferences stored in this browser.
